zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - GhostSec Announces Return to Hacktivism
  • State Hackers Turn to Massive ORB Proxy Networks to Evade Detection
  • Pro-Russian Hacktivist Claims Cyberattack Defacing Website of Medical Supply Store

ZeroFox Intelligence Flash Report - GhostSec Announces Return to Hacktivism

Source: https://www.zerofox.com/advisories/23590/

What happened: On May 15, the threat group “GhostSec” announced on its official Telegram channel its intention to abandon financially motivated cybercrime and resume hacktivism activities. GhostSec is a member of the Five Families, a collective of hacking groups that has conducted financially, ideologically, and politically-motivated attacks against industries across the globe.

Why it matters: GhostSec's renewed focus on hacktivism is very likely enabled by its financial success in leveraging GhostLocker ransomware-as-a-service (RaaS) in ransomware and digital extortion (R&DE) activity. In the short to medium term, GhostSec is likely to attempt disruptive and undermining attacks against the Israeli government, as well as other state institutions that are politically and ideologically misaligned with the group.

State Hackers Turn to Massive ORB Proxy Networks to Evade Detection

Source: https://www.bleepingcomputer.com/news/security/state-hackers-turn-to-massive-orb-proxy-networks-to-evade-detection/

What happened: China-linked actors are evading detection by relying on operational relay box (ORB) networks to conduct cyberespionage campaigns. ORBs are proxy server networks managed by independent cybercriminals who provide access to multiple state-sponsored actors.

Why it matters: The increasing use of ORBs make it more difficult for defenders to detect, attribute, and effectively identify indicators of compromise. This is concerning because these threat actors have targeted critical infrastructure, government agencies, and other prominent entities.

Pro-Russian Hacktivist Claims Cyberattack Defacing Website of Medical Supply Store

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/64839

What happened: Pro-Russian hacktivist group Just Evil has claimed a website defacement cyberattack targeting a U.S.-based medical supply store, in which it has also allegedly breached payment information belonging to clients and customers. The website is operational at the time of reporting.

Why it matters: Killmilk, the founder of Just Evil, is also a founder and former leader of another infamous pro-Russian hacktivist group, Killnet. With the emergence of Just Evil in January 2024, Killmilk has already targeted organizations in the United States, Lithuania, and Poland. Killmilk is likely to engage in more hacktivism efforts targeting the U.S. and the European Union elections to spread pro-Russian propaganda and re-assert their reputation in the hacktivist underworld.

DEEP AND DARK WEB INTELLIGENCE

Threat actor "P0f" | The untested threat actor "P0f" advertised web panel access to Network Operations Center (NOC) of an unnamed African 4G operator on the predominantly Russian language Dark Web forum "XSS." According to "P0f" the web panel contains 3,000 devices with hostnames including HUAWEI, BSC, RNC, VoIP, VPN.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-4701: It is a critical path traversal flaw in Genie software versions prior to 4.3.18, posing a severe risk of remote code execution. This vulnerability has a critical CVSS score of 9.9. Exploiting this vulnerability can grant attackers unauthorized access to Netflix's Genie platform, potentially compromising valuable data and internal services.

Affected products: Genie software versions prior to 4.3.18.

Tags: DIB, tlp:green